open-menu
closeme
.RDP File Created By Uncommon Application
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Abuse of Service Permissions to Hide Services Via Set-Service
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Abuse of Service Permissions to Hide Services Via Set-Service - PS
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Abusing Print Executable
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Account Created And Deleted Within A Close Time Frame
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Account Disabled or Blocked for Sign in Attempts
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Account Tampering - Suspicious Failed Logon Reasons
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Activity From Anonymous IP Address
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
AddinUtil.EXE Execution From Uncommon Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Addition of SID History to Active Directory Object
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1134.005
·
Share on:
twitter
facebook
linkedin
copy
Admin User Remote Logon
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.lateral-movement
attack.initial-access
attack.stealth
attack.t1078.001
attack.t1078.002
attack.t1078.003
car.2016-04-005
·
Share on:
twitter
facebook
linkedin
copy
ADS Zone.Identifier Deleted By Uncommon Application
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
AgentExecutor PowerShell Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
cve.2021-34527
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Application AppID Uri Configuration Changes
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.stealth
attack.t1552
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Application URI Configuration Changes
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1528
attack.t1078.004
attack.persistence
attack.credential-access
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Application Using Device Code Authentication Flow
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Applications That Are Using ROPC Authentication Flow
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
AppX Located in Known Staging Directory Added to Deployment Pipeline
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
AppX Located in Uncommon Directory Added to Deployment Pipeline
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
AppX Package Deployment Failed Due to Signing Requirements
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
APT PRIVATELOG Image Load Pattern
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
APT27 - Emissary Panda Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
APT29 2018 Phishing Campaign CommandLine Indicators
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
APT29 2018 Phishing Campaign File Indicators
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via IMEWDBLD.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via MSEDGE_PROXY.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via MSOHTMED.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via MSPUB.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via PresentationHost.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary File Download Via Squirrel.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Arbitrary MSI Download Via Devinit.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Aruba Network Service Potential DLL Sideloading
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
ASLR Disabled Via Sysctl or Direct Syscall - Linux
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1685
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
AspNetCompiler Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Assembly Loading Via CL_LoadAssembly.ps1
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Atbroker Registry Change
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1218
attack.persistence
attack.t1547
·
Share on:
twitter
facebook
linkedin
copy
Atomic MacOS Stealer - Persistence Indicators
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1564.001
attack.t1543.004
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Atypical Travel
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Audit CVE Event
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1203
attack.privilege-escalation
attack.t1068
attack.t1211
attack.credential-access
attack.t1212
attack.lateral-movement
attack.t1210
attack.impact
attack.t1499.004
·
Share on:
twitter
facebook
linkedin
copy
Authentications To Important Apps Using Single Factor Authentication
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
AWS Bucket Deleted
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser LoginProfile Creation
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser Templated S3 Bucket Policy Creation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.009
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS IAM S3Browser User or AccessKey Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.initial-access
attack.stealth
attack.t1059.009
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Key Pair Import Activity
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
AWS Root Credentials
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS SAML Provider Deletion Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078.004
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.t1531
attack.impact
·
Share on:
twitter
facebook
linkedin
copy
AWS Successful Console Login Without MFA
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
AWS Suspicious SAML Activity
calendar
Apr 28, 2026
·
attack.initial-access
attack.lateral-movement
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078
attack.t1548
attack.t1550
attack.t1550.001
·
Share on:
twitter
facebook
linkedin
copy
AWS VPC Flow Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Only Single Factor Authentication Required
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.defense-impairment
attack.t1078.004
attack.t1556.006
·
Share on:
twitter
facebook
linkedin
copy
Azure AD Threat Intelligence
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Azure Domain Federation Settings Modified
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Admission Controller
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Azure Login Bypassing Conditional Access Policies
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Owner Removed From Application or Service Principal
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Azure Service Principal Created
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Azure Service Principal Removed
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via ActivityLogs
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Azure Subscription Permission Elevation Via AuditLogs
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Azure Unusual Authentication Interruption
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
BaaUpdate.exe Suspicious DLL Load
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Backup Catalog Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Base64 Encoded PowerShell Command Detected
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1140
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Binary Padding - Linux
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
Binary Padding - MacOS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
Binary Proxy Execution Via Dotnet-Trace.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket User Login Failure
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Bitlocker Key Retrieval
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
BitLockerTogo.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Download From Direct IP
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Download From File Sharing Domains
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Download To Potential Suspicious Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job Downloading File Potential Suspicious Extension
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
BITS Transfer Job With Uncommon Or Suspicious Remote TLD
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
Bitsadmin to Uncommon IP Server Address
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1071.001
attack.persistence
attack.t1197
attack.s0190
·
Share on:
twitter
facebook
linkedin
copy
Bitsadmin to Uncommon TLD
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1071.001
attack.persistence
attack.t1197
attack.s0190
·
Share on:
twitter
facebook
linkedin
copy
Browser Execution In Headless Mode
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1105
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Bypass UAC via CMSTP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1548.002
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
C# IL Code Compilation Via Ilasm.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Certificate Exported Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Changes To PIM Settings
calendar
Apr 28, 2026
·
attack.initial-access
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Changing Existing Service ImagePath Value Via Reg.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Cisco BGP Authentication Failures
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Cisco Clear Logs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Cisco Duo Successful MFA Authentication Via Bypass Code
calendar
Apr 28, 2026
·
attack.credential-access
attack.initial-access
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Cisco File Deletion
calendar
Apr 28, 2026
·
attack.impact
attack.stealth
attack.t1070.004
attack.t1561.001
attack.t1561.002
·
Share on:
twitter
facebook
linkedin
copy
Cisco LDP Authentication Failures
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Clearing Windows Console History
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Cmd Launched with Hidden Start Flags to Suspicious Targets
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Process Access
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.003
attack.execution
attack.t1559.001
attack.g0069
attack.g0080
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Process Creation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CMSTP Execution Registry Event
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CMSTP UAC Bypass via COM Object Access
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1548.002
attack.t1218.003
attack.g0069
car.2019-04-001
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Load by Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe Pattern Regex
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
CobaltStrike Named Pipe Patterns
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
stp.1k
·
Share on:
twitter
facebook
linkedin
copy
Code Execution via Pcwutl.dll
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Code Injection by ld.so Preload
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
CodePage Modification Via MODE.COM To Russian Language
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL Persistence Service Creation
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Anonymous User Process Execution
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Cleanup Command Execution
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COLDSTEEL RAT Service Persistence Execution
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
COM Object Execution via Xwizard.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.001
detection.emerging-threats
cve.2025-57788
·
Share on:
twitter
facebook
linkedin
copy
Control Panel Items
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1218.002
attack.persistence
attack.t1546
·
Share on:
twitter
facebook
linkedin
copy
ConvertTo-SecureString Cmdlet Usage Via CommandLine
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
CrashControl CrashDump Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1564
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Created Files by Microsoft Sync Center
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
CreateDump Process Dump
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Creation Of a Suspicious ADS File Outside a Browser Download
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Non-Existent System DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Creation Of Pod In System Namespace
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Creation of WerFault.exe/Wer.dll in Unusual Folder
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Csc.EXE Execution Form Potentially Suspicious Parent
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1059.007
attack.t1218.005
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Curl Download And Execute Combination
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Custom File Open Handler Executes PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Decode Base64 Encoded Text
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Decode Base64 Encoded Text -MacOs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Deployment AppX Package Was Blocked By AppLocker
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Detection of PowerShell Execution via Sqlps.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Device Registration or Join Without MFA
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
DeviceCredentialDeployment Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Devtoolslauncher.exe Executes Specified Binary
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DHCP Callout DLL Installation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Error Failed Loading the CallOut DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DHCP Server Loaded the CallOut DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
cve.2022-30190
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT DLL Sideloading Indicators
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Directory Removal Via Rmdir
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Disable Administrative Share Creation at Startup
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Disable of ETW Trace - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Disable Powershell Command History
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Diskshadow Script Mode - Execution From Potential Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Diskshadow Script Mode - Uncommon Script Extension Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Displaying Hidden Files Feature Disabled
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Execution via Rasautou.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DLL Execution Via Register-cimprovider.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
DLL Load By System Process From Suspicious Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
DLL Loaded From Suspicious Location Via Cmspt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
DLL Loaded via CertOC.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
DLL Names Used By SVR For GraphicalProton Backdoor
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
DLL Search Order Hijackig Via Additional Space in Path
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading by VMware Xfer Utility
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DLL Sideloading Of ShellChromeAPI.DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Dllhost.EXE Execution Anomaly
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
DllUnregisterServer Function Call Via Msiexec.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
DMSA Link Attributes Modified
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.002
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
DMSA Service Account Created in Specific OUs - PowerShell
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.002
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
DNS Query Request By Regsvr32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1559.001
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
DNS Server Error Failed Loading the ServerLevelPluginDLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
DNS-over-HTTPS Enabled by Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1140
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
DotNet CLR DLL Loaded By Scripting Applications
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Driver Added To Disallowed Images In HVCI - Registry
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Driver/DLL Installation Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Drop Binaries Into Spool Drivers Color Folder
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
DumpMinitool Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Dynamic .NET Compilation Via Csc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Dynamic CSharp Compile Artefact
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Enable BPF Kprobes Tracing
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Enable Local Manifest Installation With Winget
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Enabling COR Profiler Environment Variables
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.012
·
Share on:
twitter
facebook
linkedin
copy
Equation Group DLL_U Export Function Load
calendar
Apr 28, 2026
·
attack.stealth
attack.g0020
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ETW Trace Evasion Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
EventLog EVTX File Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
EvilNum APT Golden Chickens Deployment Via OCX Files
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exchange PowerShell Cmdlet History Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Execute Code with Pester.bat
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Execute Code with Pester.bat as Parent
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Execute Files with Msdeploy.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Execute From Alternate Data Streams
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Execute Pcwrun.EXE To Leverage Follina
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Execution DLL of Choice Using WAB.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Execution Of Non-Existing File
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Execution of Suspicious File Type Extension
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Execution via stordiag.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Execution via WorkFolders.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Exploit for CVE-2015-1641
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
cve.2015-1641
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Exploiting SetupComplete.cmd CVE-2019-1378
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1068
attack.execution
attack.t1059.003
attack.t1574
cve.2019-1378
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Explorer Process Tree Break
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Exports Registry Key To an Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
External Remote RDP Logon from Public IP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
External Remote SMB Logon from Public IP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Authentications From Countries You Do Not Operate Out Of
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Failed Code Integrity Checks
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.001
·
Share on:
twitter
facebook
linkedin
copy
Failed Logon From Public IP
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.t1190
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Fax Service DLL Search Order Hijack
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
File Decoded From Base64/Hex Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File Deleted Via Sysinternals SDelete
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
File Deletion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
File Deletion Via Del
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
File Download Using ProtocolHandler.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Bitsadmin To A Suspicious Target Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download Via InstallUtil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
File Download Via Windows Defender MpCmpRun.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
File Download with Headless Browser
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1105
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
File Encoded To Base64 Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File In Suspicious Location Encoded To Base64 Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
File Time Attribute Change
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
File Time Attribute Change - Linux
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
File With Suspicious Extension Downloaded Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Files With System DLL Name In Unsuspected Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Files With System Process Name In Unsuspected Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Filter Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Findstr Launching .lnk File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1202
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Fireball Archer Install
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Flash Player Update from Suspicious Location
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1189
attack.execution
attack.t1204.002
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Forest Blizzard APT - Process Creation Activity
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Forfiles.EXE Child Process Masquerading
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Fsutil Suspicious Invocation
calendar
Apr 28, 2026
·
attack.impact
attack.stealth
attack.t1070
attack.t1485
·
Share on:
twitter
facebook
linkedin
copy
Github New Secret Created
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Github Self Hosted Runner Changes Detected
calendar
Apr 28, 2026
·
attack.impact
attack.discovery
attack.collection
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1526
attack.t1213.003
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Github SSH Certificate Configuration Changed
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Goofy Guineapig Backdoor IOC
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Kubernetes Admission Controller
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Google Workspace Government Attack Warning
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.impact
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Gpscript Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Greedy File Deletion Using Del
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Greenbug Espionage Group Indicators
calendar
Apr 28, 2026
·
attack.stealth
attack.g0049
attack.execution
attack.t1059.001
attack.command-and-control
attack.t1105
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Guest Account Enabled Via Sysadminctl
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
attack.t1078.001
·
Share on:
twitter
facebook
linkedin
copy
Guest User Invited By Non Approved Inviters
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Guest Users Invited To Tenant By Non Approved Inviters
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CACTUSTORCH Remote Thread Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1055.012
attack.t1059.005
attack.t1059.007
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CoercedPotato Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CoercedPotato Named Pipe Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Covenant PowerShell Launcher
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CrackMapExec PowerShell Obfuscation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - DInjector PowerShell Cradle Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EfsPotato Named Pipe Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
HackTool - F-Secure C3 Load by Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
HackTool - GMER Rootkit Detector and Remover Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
HackTool - HollowReaper Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Impersonate Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Koh Default Named Pipe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.credential-access
attack.stealth
attack.t1528
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LittleCorporal Generated Maldoc Injection
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1204.002
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - LocalPotato Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
cve.2023-21746
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
HackTool - NoFilter Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134
attack.t1134.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Potential CobaltStrike Process Injection
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Powerup Write Hijack DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
HackTool - PPID Spoofing SelectMyParent Tool Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.004
·
Share on:
twitter
facebook
linkedin
copy
HackTool - RedMimicry Winnti Playbook Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1106
attack.t1059.003
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpDPAPI Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpImpersonation Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.003
·
Share on:
twitter
facebook
linkedin
copy
HackTool - SharpUp PrivEsc Tool Execution
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.discovery
attack.execution
attack.stealth
attack.t1615
attack.t1569.002
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Wmiexec Default Powershell Command
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
HackTool - XORDump Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
HackTool Named File Stream Created
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
HH.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.001
·
Share on:
twitter
facebook
linkedin
copy
Hidden Executable In NTFS Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Hidden Files and Directories
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Hidden Flag Set On File/Directory Via Chflags - MacOS
calendar
Apr 28, 2026
·
attack.credential-access
attack.command-and-control
attack.stealth
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Hidden User Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
Hiding Files with Attrib.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Hiding User Account Via SpecialAccounts Registry Key
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
Hiding User Account Via SpecialAccounts Registry Key - CommandLine
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.002
·
Share on:
twitter
facebook
linkedin
copy
HTML Help HH.EXE Suspicious Child Process
calendar
Apr 28, 2026
·
attack.execution
attack.initial-access
attack.stealth
attack.t1047
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.007
attack.t1218
attack.t1218.001
attack.t1218.010
attack.t1218.011
attack.t1566
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Huawei BGP Authentication Failures
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Ie4uinit Lolbin Use From Invalid Path
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
IIS WebServer Access Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
IIS WebServer Log Deletion via CommandLine Utilities
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
ImagingDevices Unusual Parent/Child Processes
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Import LDAP Data Interchange Format File Via Ldifde.EXE
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1218
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Service Terminated Unexpectedly
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Important Windows Service Terminated With Error
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Impossible Travel
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Increased Failed Authentications Of Any Type
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Indirect Command Execution By Program Compatibility Wizard
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Indirect Command Execution From Script File Via Bash.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Indirect Command Execution via SFTP ProxyCommand
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Indirect Inline Command Execution Via Bash.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
InfDefaultInstall.exe .inf Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Injected Browser Process Spawning Rundll32 - GuLoader Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Insensitive Subfolder Search Via Findstr.EXE
calendar
Apr 28, 2026
·
attack.credential-access
attack.command-and-control
attack.stealth
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Interactive Bash Suspicious Children
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.004
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Invalid PIM License
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation CLIP+ Launcher - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation COMPRESS OBFUSCATION - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Obfuscated IEX Invocation - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation RUNDLL LAUNCHER - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation STDIN+ Launcher - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR+ Launcher - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Stdin - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Clip - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use MSHTA - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - PowerShell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - Security
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Invoke-Obfuscation Via Use Rundll32 - System
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
JScript Compiler Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Juniper BGP Missing MD5
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.credential-access
attack.collection
attack.stealth
attack.t1078
attack.t1110
attack.t1557
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Execution Via RunDLL32.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kapeka Backdoor Loaded Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.002
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Kavremover Dropped Binary LOLBIN Usage
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Kernel Memory Dump Via LiveKD
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Admission Controller Modification
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.credential-access
attack.t1552
attack.t1552.007
·
Share on:
twitter
facebook
linkedin
copy
Kubernetes Events Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Launch-VsDevShell.PS1 Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216.001
·
Share on:
twitter
facebook
linkedin
copy
Lazarus APT DLL Sideloading Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0032
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Lazarus System Binary Masquerading
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Archive
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Executable
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Dropped Script
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Legitimate Application Writing Files In Uncommon Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Linux Base64 Encoded Pipe to Shell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Linux Base64 Encoded Shebang In CLI
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Linux Command History Tampering
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Linux Package Uninstall
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Linux Shell Pipe to Shell
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Driver Creation By Uncommon Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
LiveKD Kernel Memory Dump File Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Login to Disabled Account
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Logon from a Risky IP Address
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
LOL-Binary Copied From System Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
LOLBIN Execution From Abnormal Drive
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Lolbin Runexehelper Use As Proxy
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Lolbin Unregmp2.exe Use As Proxy
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Lummac Stealer Activity - Execution Of More.com And Vbc.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL File Dropped in the Teams or OneDrive Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Malicious DLL Load By Compromised 3CXDesktopApp
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Malicious Named Pipe Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Malicious PE Execution by Microsoft Visual Studio Debugger
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078
attack.t1078.002
·
Share on:
twitter
facebook
linkedin
copy
Malicious Windows Script Components File Execution by TAEF Detection
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Malware Shellcode in Verclsid Target Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
ManageEngine Endpoint Central Dctask64.EXE Potential Abuse
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Masquerading as Linux Crond Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Mavinject Inject DLL Into Running Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
attack.t1218.013
·
Share on:
twitter
facebook
linkedin
copy
MaxMpxCt Registry Value Changed
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Measurable Increase Of Successful Authentications
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - Security
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Meterpreter or Cobalt Strike Getsystem Service Installation - System
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Microsoft 365 - Impossible Travel Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Defender Blocked from Loading Unsigned DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash - WER
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Office DLL Sideload
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Sync Center Suspicious Network Connections
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
MMC Executing Files with Reversed Extensions Using RTLO Abuse
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.002
attack.t1218.014
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
MMC Loading Script Engines DLLs
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218.014
·
Share on:
twitter
facebook
linkedin
copy
Modification of ld.so.preload
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.006
·
Share on:
twitter
facebook
linkedin
copy
Monitoring For Persistence Via BITS
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
Mount Execution With Hidepid Parameter
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
MpiExec Lolbin
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
MSDT Execution Via Answer File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
MSHTA Execution with Suspicious File Extensions
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
attack.t1218.005
attack.execution
attack.t1059.007
cve.2020-1599
·
Share on:
twitter
facebook
linkedin
copy
Mshtml.DLL RunHTMLApplication Suspicious Usage
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
MSI Installation From Web
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Msiexec Quiet Installation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
MsiExec Web Install
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Msxsl.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Denied
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
Multifactor Authentication Interrupted
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
attack.t1621
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated By AddinUtil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated By Regsvr32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1559.001
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Network Connection Initiated Via Notepad.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.command-and-control
attack.execution
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
New BITS Job Created Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
New BITS Job Created Via PowerShell
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
·
Share on:
twitter
facebook
linkedin
copy
New Capture Session Launched Via DXCap.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
New Country
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
New DLL Registered Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
New DMSA Service Account Created in Specific OUs
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.002
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.defense-impairment
attack.t1574.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
New File Association Using Exefile
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
New or Renamed User Account with '$' Character
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
New Process Created Via Taskmgr.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Node Process Executions
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
NotPetya Ransomware Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1218.011
attack.t1685.005
attack.credential-access
attack.t1003.001
car.2016-04-002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Nslookup PowerShell Download Cradle - ProcessCreation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
NTFS Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated PowerShell MSI Install via WindowsInstaller COM
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.010
attack.t1218.007
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Odbcconf.EXE Suspicious DLL Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Office Application Initiated Network Connection Over Uncommon Ports
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Okta New Admin Console Behaviours
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Old TLS1.0/TLS1.1 Protocol Version Enabled
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
OneNote Attachment File Dropped In Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
OneNote.EXE Execution of Malicious Embedded Scripts
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.001
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH Login Attempt
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.lateral-movement
attack.persistence
attack.stealth
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - SSH New Connection Attempt
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.lateral-movement
attack.persistence
attack.stealth
attack.t1133
attack.t1021
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenCanary - Telnet Login Attempt
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.command-and-control
attack.stealth
attack.t1133
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
OpenWith.exe Executes Specified Binary
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.stealth
attack.t1012
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Operation Wocao Activity - Security
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.discovery
attack.stealth
attack.t1012
attack.t1036.004
attack.t1027
attack.execution
attack.t1053.005
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Outbound Network Connection Initiated By Cmstp.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.003
·
Share on:
twitter
facebook
linkedin
copy
Outbound Network Connection To Public IP Via Winlogon
calendar
Apr 28, 2026
·
attack.execution
attack.command-and-control
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Outlook EnableUnsafeClientMailRules Setting Enabled
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened (Email Attachment)
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1027
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Password Protected ZIP File Opened (Suspicious Filenames)
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1027
attack.t1105
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Password Provided In Command Line Of Net.EXE
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.lateral-movement
attack.stealth
attack.t1021.002
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Password Reset By User Account
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.credential-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Payload Decoded and Decrypted via Built-in Utilities
calendar
Apr 28, 2026
·
attack.stealth
attack.t1059
attack.t1204
attack.execution
attack.t1140
attack.s0482
attack.s0402
·
Share on:
twitter
facebook
linkedin
copy
PDF File Created By RegEdit.EXE
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Pikabot Fake DLL Extension Execution Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PIM Alert Setting Changes To Disabled
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
PIM Approvals And Deny Elevation
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Ping Hex IP
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor DLL Loading Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Pingback Backdoor File Indicators
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Possible Privilege Escalation via Weak Service Permissions
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential 7za.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Access Token Abuse
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
stp.4u
·
Share on:
twitter
facebook
linkedin
copy
Potential Antivirus Software DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Application Whitelisting Bypass via Dnx.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Potential appverifUI.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Code Execution Via Node.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Command Execution Using Msdt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary Command Execution Via FTP.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary DLL Load Using Winword
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary File Download Using Office Application
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential Arbitrary File Download Via Cmdl32.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potential AVKkid.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Azure Browser SSO Abuse
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Baby Shark Malware Activity
calendar
Apr 28, 2026
·
attack.execution
attack.discovery
attack.stealth
attack.t1012
attack.t1059.003
attack.t1059.001
attack.t1218.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Base64 Decoded From Images
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Impersonating Sysinternals Tools
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Proxy Execution Via Cdb.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1106
attack.t1218
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potential Binary Proxy Execution Via VSDiagnostics.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential BlackByte Ransomware Activity
calendar
Apr 28, 2026
·
attack.execution
attack.impact
attack.stealth
attack.t1485
attack.t1498
attack.t1059.001
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Bumblebee Remote Thread Creation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
attack.t1059.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerDU.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential CCleanerReactivator.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Chrome Frame Helper DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL Persistence Service DLL Creation
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL Persistence Service DLL Load
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential COLDSTEEL RAT File Indicators
calendar
Apr 28, 2026
·
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Command Line Path Traversal Evasion Attempt
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potential Commandline Obfuscation Using Escape Characters
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Compromised 3CXDesktopApp Update Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2023-36884 Exploitation Dropped File
calendar
Apr 28, 2026
·
attack.persistence
cve.2023-36884
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
cve.2024-3400
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Data Stealing Via Chromium Headless Debugging
calendar
Apr 28, 2026
·
attack.credential-access
attack.collection
attack.stealth
attack.t1185
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Binary Rename
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
calendar
Apr 28, 2026
·
attack.stealth
attack.t1006
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Potential Defense Evasion Via Right-to-Left Override
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Devil Bait Malware Reconnaissance
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Devil Bait Related Indicator
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Injection Or Execution Using Tracker.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGCORE.DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DBGHELP.DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of DbgModel.DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MpSvc.DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of MsCorSvc.DLL
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Of Non-Existent DLLs From System Folders
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Using Coregen.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1218
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via ClassicExplorer32.dll
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via comctl32.dll
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via DeviceEnroller.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via JsSchHlp
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential DLL Sideloading Via VMware Xfer
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Dridex Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.discovery
attack.t1135
attack.t1033
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential EACore.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Edputil.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Emotet Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Emotet Rundll32 Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential EmpireMonkey Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Encoded PowerShell Patterns In CommandLine
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation Attempt From Office Application
calendar
Apr 28, 2026
·
attack.execution
cve.2021-40444
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1105
detection.emerging-threats
cve.2025-33053
·
Share on:
twitter
facebook
linkedin
copy
Potential Fake Instance Of Hxtsr.EXE Executed
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potential File Download Via MS-AppInstaller Protocol Handler
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential File Extension Spoofing Using Right-to-Left Override
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1036.002
·
Share on:
twitter
facebook
linkedin
copy
Potential Goofy Guineapig GoolgeUpdate Process Anomaly
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Goopdate.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Homoglyph Attack Using Lookalike Characters
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Homoglyph Attack Using Lookalike Characters in Filename
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential In-Memory Execution Using Reflection.Assembly
calendar
Apr 28, 2026
·
attack.stealth
attack.t1620
·
Share on:
twitter
facebook
linkedin
copy
Potential Initial Access via DLL Search Order Hijacking
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1566
attack.t1566.001
attack.initial-access
attack.t1574
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Iviewers.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential JLI.dll Side-Loading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Kapeka Decrypted Backdoor Indicator
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential LethalHTA Technique Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
Potential Libvlc.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Linux Process Code Injection Via DD Utility
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
Potential LSASS Process Dump Via Procdump
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.credential-access
attack.t1003.001
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Potential Malicious AppX Package Installation Attempts
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Manage-bde.wsf Abuse To Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Potential Memory Dumping Activity Via LiveKD
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Meterpreter/CobaltStrike Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.001
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Potential MFA Bypass Using Legacy Client Authentication
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Potential Mfdetours.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mftrace.EXE Abuse
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading Via Defender Binaries
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential MsiExec Masquerading
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Potential MuddyWater APT Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.g0069
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Notepad++ CVE-2025-49144 Exploitation
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.008
cve.2025-49144
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential NTLM Coercion Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Obfuscated Ordinal Call Via Rundll32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Potential Password Spraying Attempt Using Dsacls.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential PendingFileRenameOperations Tampering
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Persistence Attempt Via Existing Service Tampering
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1543.003
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Pikabot Hollowing Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.012
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1059.003
attack.t1105
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential PlugX Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.s0013
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Command Line Obfuscation
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1027
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Execution Via DLL
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Using Alias Cmdlets
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1027
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Using Character Join
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1027
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Via Reversed Commands
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Potential PowerShell Obfuscation Via WCHAR/CHAR
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Potential PrintNightmare Exploitation Attempt
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574
cve.2021-1675
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation Attempt Via .Exe.Local Technique
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Service Permissions Weakness
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Execution Proxy Via CL_Invocation.ps1
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Hollowing Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
Potential Process Injection Via Msra.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Potential Provisioning Registry Key Abuse For Binary Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Provlaunch.EXE Binary Proxy Execution Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Python DLL SideLoading
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Qakbot Rundll32 Execution
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
attack.persistence
attack.t1542.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin Aclui Dll SideLoading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Raspberry Robin CPL Execution Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Rcdll.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential ReflectDebugger Content Execution Via WerFault.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potential Register_App.Vbs LOLScript Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Registry Persistence Attempt Via DbgManagedDebugger
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574
·
Share on:
twitter
facebook
linkedin
copy
Potential Regsvr32 Commandline Flag Anomaly
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potential Remote SquiblyTwo Technique Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1047
attack.t1220
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Potential RemoteFXvGPUDisablement.EXE Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Default Location
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RjvPlatform.DLL Sideloading From Non-Default Location
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential RoboForm.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Rundll32 Execution With DLL Stored In ADS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Potential Secure Deletion with SDelete
calendar
Apr 28, 2026
·
attack.impact
attack.stealth
attack.defense-impairment
attack.t1070.004
attack.t1027.005
attack.t1485
attack.t1553.002
attack.s0195
·
Share on:
twitter
facebook
linkedin
copy
Potential ShellDispatch.DLL Functionality Abuse
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential ShellDispatch.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Signing Bypass Via Windows Developer Features
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Signing Bypass Via Windows Developer Features - Registry
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential SmadHook.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential SolidPDFCreator.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Activity Using SeCEdit
calendar
Apr 28, 2026
·
attack.collection
attack.discovery
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.execution
attack.stealth
attack.defense-impairment
attack.t1685.001
attack.t1547.001
attack.t1505.005
attack.t1556.002
attack.t1685
attack.t1574.007
attack.t1564.002
attack.t1546.008
attack.t1546.007
attack.t1547.014
attack.t1547.010
attack.t1547.002
attack.t1557
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious BPF Activity - Linux
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Child Process Of 3CXDesktopApp
calendar
Apr 28, 2026
·
attack.command-and-control
attack.execution
attack.stealth
attack.t1218
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Mofcomp Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Windows Feature Enabled
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Windows Feature Enabled - ProcCreation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Winget Package Installation
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potential SysInternals ProcDump Evasion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Potential System DLL Sideloading From Non System Locations
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Vcruntime140 DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Vivaldi_elf.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Waveedit.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential Wazuh Security Platform DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potential WerFault ReflectDebugger Registry Value Abuse
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Potential Winnti Dropper Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Potential WWlib.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Over Permissive Permissions Granted Using Dsacls.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious ASP.NET Compilation Via AspNetCompiler
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Cabinet File Expansion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of ClickOnce Application
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of DiskShadow.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process of KeyScrambler.exe
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1203
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of Regsvr32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Process Of VsCode
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Child Processes Spawned by ConHost
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious CMD Shell Output Redirect
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious DLL Registered Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious DMP/HDMP File Creation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution From Parent Process In Public Folder
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1564
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution From Tmp Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious File Download From ZIP TLD
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious GoogleUpdate Child Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Office Document Executed From Trusted Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Ping/Copy Command Combination
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Regsvr32 HTTP IP Pattern
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Regsvr32 HTTP/FTP Pattern
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Rundll32 Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Rundll32.EXE Execution of UDL File
calendar
Apr 28, 2026
·
attack.execution
attack.command-and-control
attack.stealth
attack.t1218.011
attack.t1071
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Self Extraction Directive File Created
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Windows App Activity
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Potentially Suspicious Wuauclt Network Connection
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded FromBase64String Cmdlet
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded Invoke Keyword
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded Reflective Assembly Load
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
attack.t1620
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Base64 Encoded WMI Classes
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Console History Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Core DLL Loaded Via Office Application
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Decompress Commands
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Deleted Mounted Share
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Powershell Detect Virtualization Environment
calendar
Apr 28, 2026
·
attack.discovery
attack.stealth
attack.t1497.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Executed From Headless ConHost Process
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1059.003
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Logging Disabled Via Registry Key Tampering
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1564.001
attack.t1112
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
PowerShell MSI Install via WindowsInstaller COM From Remote Location
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Script Change Permission Via Set-Acl
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Set-Acl On Windows Folder
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PowerShell ShellCode
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Powershell Store File In Alternate Data Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Powershell Timestomp
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
Powershell Token Obfuscation - Process Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.009
·
Share on:
twitter
facebook
linkedin
copy
PowerShell WMI Win32_Product Install MSI
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Prefetch File Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
PrintBrm ZIP Creation of Extraction
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1105
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Privileged Account Creation
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Procdump Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Process Access via TrolleyExpress Exclusion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Process Creation Using Sysnative Folder
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Process Deletion of Its Own Executable
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Process Execution From A Potentially Suspicious Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Process Launched Without Image Name
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Process Memory Dump Via Comsvcs.DLL
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1036
attack.t1003.001
car.2013-05-009
·
Share on:
twitter
facebook
linkedin
copy
Process Memory Dump Via Dotnet-Dump
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Process Proxy Execution Via Squirrel.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Program Executed Using Proxy/Local Command Via SSH.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Proxy Execution via Vshadow
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Proxy Execution Via Wuauclt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Ps.exe Renamed SysInternals Tool
calendar
Apr 28, 2026
·
attack.stealth
attack.g0035
attack.t1036.003
car.2013-05-009
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
PSScriptPolicyTest Creation By Uncommon Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Execution
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.stealth
attack.t1564.003
attack.t1134.002
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
PUA - AdvancedRun Suspicious Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
PUA - DefenderCheck Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.005
·
Share on:
twitter
facebook
linkedin
copy
PUA - Potential PE Metadata Tamper Using Rcedit
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
attack.t1036
attack.t1027.005
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
PUA - Process Hacker Execution
calendar
Apr 28, 2026
·
attack.discovery
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1622
attack.t1564
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
PUA - System Informer Execution
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.discovery
attack.stealth
attack.t1082
attack.t1564
attack.t1543
·
Share on:
twitter
facebook
linkedin
copy
Publisher Attachment File Dropped In Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Pubprn.vbs Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216.001
·
Share on:
twitter
facebook
linkedin
copy
Python Image Load By Non-Python Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.002
·
Share on:
twitter
facebook
linkedin
copy
Python One-Liners with Base64 Decoding
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.006
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Python One-Liners with Base64 Decoding - Linux
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.006
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Regsvr32 Calc Pattern
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Rundll32 Exports Execution
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Qakbot Rundll32 Fake DLL Extension Execution
calendar
Apr 28, 2026
·
attack.execution
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Rare Remote Thread Creation By Uncommon Source Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
RedSun - Conhost.exe Spawned by TieringEngineService.exe
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.002
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - Named Pipe Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1055
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - TieringEngineService.exe Detected as EICAR Test File
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1036.005
attack.t1685
attack.privilege-escalation
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RegAsm.EXE Execution Without CommandLine Flags or Files
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
RegAsm.EXE Initiating Network Connection To Public IP
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.009
·
Share on:
twitter
facebook
linkedin
copy
REGISTER_APP.VBS Proxy Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Registry Modification for OCI DLL Redirection
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.defense-impairment
attack.t1112
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Registry Persistence via Service in Safe Mode
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Registry-Free Process Scope COR_PROFILER
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.012
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Suspicious File Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 DLL Execution With Uncommon Extension
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1574
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 Execution From Highly Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Regsvr32 Execution From Potential Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - NetSupport Execution From Unusual Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Renamed MeshAgent Execution - MacOS
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1219.002
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - Renamed MeshAgent Execution - Windows
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
attack.t1219.002
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Access Tool - RURAT Execution From Unusual Location
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Remote AppX Package Downloaded from File Sharing or CDN Domain
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Remote CHM File Download/Execution Via HH.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.001
·
Share on:
twitter
facebook
linkedin
copy
Remote Code Execute via Winrm.vbs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Remote File Download Via Findstr.EXE
calendar
Apr 28, 2026
·
attack.credential-access
attack.command-and-control
attack.stealth
attack.t1218
attack.t1564.004
attack.t1552.001
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation By Uncommon Source Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation In Uncommon Target Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.003
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation Ttdinject.exe Proxy
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Remote Thread Creation Via PowerShell In Uncommon Target
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Remote XSL Execution Via Msxsl.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Remotely Hosted HTA File Executed Via Mshta.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
Remove Exported Mailbox from Exchange Webserver
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Remove Scheduled Cron Task/Job
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed AutoHotkey.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed AutoIt Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Renamed BrowserCore.EXE Execution
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1528
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed CreateDump Utility Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1003.001
attack.credential-access
·
Share on:
twitter
facebook
linkedin
copy
Renamed CURL.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed FTP.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed Jusched.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed Mavinject.EXE Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.001
attack.t1218.013
·
Share on:
twitter
facebook
linkedin
copy
Renamed MegaSync Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Renamed Microsoft Teams Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed Msdt.EXE Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed NetSupport RAT Execution
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Renamed NirCmd.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed Office Binary Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed PAExec Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed PingCastle Binary Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Renamed Plink Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Renamed Powershell Under Powershell Channel
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed ProcDump Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Renamed Remote Utilities RAT (RURAT) Execution
calendar
Apr 28, 2026
·
attack.collection
attack.command-and-control
attack.discovery
attack.stealth
attack.s0592
·
Share on:
twitter
facebook
linkedin
copy
Renamed Schtasks Execution
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1036.003
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Renamed Vmnat.exe Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Renamed ZOHO Dctask64 Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1036
attack.t1055.001
attack.t1202
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Response File Execution Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Rhadamanthys Stealer Module Launch Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Roles Activated Too Frequently
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Activation Doesn't Require MFA
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Are Not Being Used
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Roles Assigned Outside PIM
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Root Account Enable Via Dsenableroot
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1078
attack.t1078.001
attack.t1078.003
attack.initial-access
attack.persistence
·
Share on:
twitter
facebook
linkedin
copy
Run PowerShell Script from ADS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Execution With Uncommon DLL Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Execution Without CommandLine Parameters
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 InstallScreenSaver Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Internet Connection
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Spawned Via Explorer.EXE
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
RunDLL32 Spawning Explorer
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 UNC Path Execution
calendar
Apr 28, 2026
·
attack.execution
attack.lateral-movement
attack.stealth
attack.t1021.002
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
RunMRU Registry Key Deletion
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
RunMRU Registry Key Deletion - Registry
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation Masquerading as System Processes
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.stealth
attack.t1053.005
attack.t1036.004
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Scheduled Task Creation with Curl and PowerShell Execution Combo
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.stealth
attack.t1053.005
attack.t1218
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
SCR File Write Event
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
ScreenConnect - SlashAndGrab Exploitation Indicators
calendar
Apr 28, 2026
·
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
ScreenSaver Registry Key Set
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Scripting/CommandLine Process Spawned Regsvr32
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Sdiagnhost Calling Suspicious Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Self Extraction Directive File Created In Potentially Suspicious Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Sensitive File Dump Via Print.EXE
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1003.003
attack.t1003.002
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Server Side Template Injection Strings
calendar
Apr 28, 2026
·
attack.stealth
attack.t1221
·
Share on:
twitter
facebook
linkedin
copy
Service DACL Abuse To Hide Services Via Sc.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Key Read Access Request
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Permissions Weakness Check
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.011
stp.2a
·
Share on:
twitter
facebook
linkedin
copy
Service Security Descriptor Tampering Via Sc.EXE
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
SES Identity Has Been Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Set Suspicious Files as System Files Using Attrib.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Setup16.EXE Execution With Custom .Lst File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.005
·
Share on:
twitter
facebook
linkedin
copy
Shell32 DLL Execution in Suspicious Directory
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Sign-in Failure Due to Conditional Access Requirements Not Met
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins by Unknown Devices
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Sign-ins from Non-Compliant Devices
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Silenttrinity Stager Msbuild Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127.001
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware CommandLine Indicator
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Small Sieve Malware File Indicator Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Sofacy Trojan Loader Activity
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.g0007
attack.t1059.003
attack.t1218.011
car.2013-10-002
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Space After Filename - macOS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.006
·
Share on:
twitter
facebook
linkedin
copy
SQL Client Tools PowerShell Session Detection
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Stale Accounts In A Privileged Role
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Start of NT Virtual DOS Machine
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Steganography Extract Files with Steghide
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Hide Files with Steghide
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Hide Zip Information in Picture File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Steganography Unzip Hidden Information From Picture File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.003
·
Share on:
twitter
facebook
linkedin
copy
Successful Authentications From Countries You Do Not Operate Out Of
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Suspect Svchost Activity
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Advpack Call Via Rundll32.EXE
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious AgentExecutor PowerShell Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious BitLocker Access Agent Update Utility Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.lateral-movement
attack.t1021.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Browser Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Cabinet File Execution Via Msdt.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Calculator Usage
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Created as System
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1134.002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process of AspNetCompiler
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of BgInfo.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Child Process Of Wermgr.EXE
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CodePage Switch Via CHCP
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Account Name Change CVE-2021-42287
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1036
attack.t1098
cve.2021-42287
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Computer Machine Password by PowerShell
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Control Panel DLL Load
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Copy From or To System Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Creation with Colorcpl
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Csi.exe Usage
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.execution
attack.stealth
attack.t1072
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious CustomShellHost Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Diantz Alternate Data Stream Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Digital Signature Of AppX Package
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DLL Loaded via CertOC.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DotNET CLR Usage Log Artifact
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Double Extension Files
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download From Direct IP Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download From File-Sharing Website Via Bitsadmin
calendar
Apr 28, 2026
·
attack.persistence
attack.execution
attack.stealth
attack.t1197
attack.s0190
attack.t1036.003
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Download Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Driver/DLL Installation Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious DumpMinitool Execution
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1036
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Environment Variable Has Been Registered
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Executable File Creation
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Execution of InstallUtil Without Log
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.004
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Extrac32 Alternate Data Stream Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created by ArcSOC.exe
calendar
Apr 28, 2026
·
attack.command-and-control
attack.persistence
attack.initial-access
attack.execution
attack.stealth
attack.t1127
attack.t1105
attack.t1133
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Created Via OneNote Application
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation Activity From Fake Recycle.Bin Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Creation In Uncommon AppData Folder
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Download From File Sharing Websites - File Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Downloaded From Direct IP Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
Suspicious File Encoded To Base64 Via Certutil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Filename with Embedded Base64 Commands
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.004
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Files in Default GPO Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Get-Variable.exe Creation
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1546
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious GUP Usage
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious HH.EXE Execution
calendar
Apr 28, 2026
·
attack.execution
attack.initial-access
attack.stealth
attack.t1047
attack.t1059.001
attack.t1059.003
attack.t1059.005
attack.t1059.007
attack.t1218
attack.t1218.001
attack.t1218.010
attack.t1218.011
attack.t1566
attack.t1566.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious High IntegrityLevel Conhost Legacy Option
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Hyper-V Cmdlets
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.006
·
Share on:
twitter
facebook
linkedin
copy
Suspicious IIS URL GlobalRules Rewrite Via AppCmd
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Inbox Manipulation Rules
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
·
Share on:
twitter
facebook
linkedin
copy
Suspicious IO.FileStream
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious JavaScript Execution Via Mshta.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious LNK Double Extension File Created
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Login Activity Classified By Google
calendar
Apr 28, 2026
·
attack.initial-access
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Microsoft Office Child Process
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1047
attack.t1204.002
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msbuild Execution By Uncommon Parent Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious MSDT Parent Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious MSHTA Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.005
car.2013-02-003
car.2013-03-001
car.2014-04-003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious MsiExec Embedding Parent
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msiexec Execute Arbitrary DLL
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Msiexec Quiet Install From Remote Location
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Network Connection Binary No CommandLine
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Obfuscated PowerShell Code
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Parent Double Extension File Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.007
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Ping/Del Command Combination
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Powercfg Execution To Change Lock Screen Timeout
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell Invocations - Specific - ProcessCreation
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PowerShell WindowStyle Option
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Printer Driver Empty Manufacturer
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574
cve.2021-1675
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Execution From Fake Recycle.Bin Folder
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Masquerading As SvcHost.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Parents
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Start Locations
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
car.2013-05-002
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Provlaunch.EXE Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Regsvr32 Execution From Remote Share
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Child Process From Outlook
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Remote Logon with Explicit Credentials
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
attack.lateral-movement
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Response File Execution Via Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Activity Invoking Sys File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Execution With Image Extension
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Invoking Inline VBScript
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Rundll32 Setupapi.dll Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Runscripthelper.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation via Masqueraded XML File
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.persistence
attack.stealth
attack.t1036.005
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Binary Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service DACL Modification Via Set-Service Cmdlet - PS
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Set Value of MSDT in Registry (CVE-2022-30190)
calendar
Apr 28, 2026
·
attack.stealth
attack.t1221
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ShellExec_RunDLL Call Via Ordinal
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SignIns From A Non Registered Device
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Space Characters in RunMRU Registry Path - ClickFix
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.004
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Space Characters in TypedPaths Registry Path - FileFix
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1204.004
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Speech Runtime Binary Child Process
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.stealth
attack.t1021.003
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Splwow64 Without Params
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Start-Process PassThru
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
Suspicious SYSTEM User Process Creation
calendar
Apr 28, 2026
·
attack.credential-access
attack.privilege-escalation
attack.stealth
attack.t1134
attack.t1003
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Unsigned Thor Scanner Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Usage of For Loop with Recursive Directory Search in CMD
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.003
attack.t1027.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Usage Of ShellExec_RunDLL
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Use of CSharp Interactive Console
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Userinit Child Process
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Vsls-Agent Command With AgentExtensionPath Load
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Update Agent Empty Cmdline
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Suspicious WMIC Execution Via Office Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1204.002
attack.t1047
attack.t1218.010
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Suspicious WmiPrvSE Child Process
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1047
attack.t1204.002
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Wordpad Outbound Connections
calendar
Apr 28, 2026
·
attack.command-and-control
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Workstation Locking via Rundll32
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Suspicious XOR Encoded PowerShell Command
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.001
attack.t1140
attack.t1027
·
Share on:
twitter
facebook
linkedin
copy
Suspicious ZipExec Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Execute Arbitrary PowerShell Code
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer Execution to Bypass Powershell Restriction
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals Tools AppX Versions Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Error
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Modification
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
System Control Panel Item Loaded From Uncommon Location
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
System File Execution Location Anomaly
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
System Information Discovery Using System_Profiler
calendar
Apr 28, 2026
·
attack.discovery
attack.stealth
attack.t1082
attack.t1497.001
·
Share on:
twitter
facebook
linkedin
copy
System Information Discovery Via Sysctl - MacOS
calendar
Apr 28, 2026
·
attack.stealth
attack.t1497.001
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
TAIDOOR RAT DLL Load
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1055.001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Taskmgr as LOCAL_SYSTEM
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Tasks Folder Evasion
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
TeamViewer Log File Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.004
·
Share on:
twitter
facebook
linkedin
copy
Temporary Access Pass Added To An Account
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.initial-access
attack.persistence
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Terminal Server Client Connection History Cleared - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Third Party Software DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Time Travel Debugging Utility Usage
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1218
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Time Travel Debugging Utility Usage - Image
calendar
Apr 28, 2026
·
attack.credential-access
attack.stealth
attack.t1218
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Tomcat WebServer Logs Deleted
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070
·
Share on:
twitter
facebook
linkedin
copy
Too Many Global Admins
calendar
Apr 28, 2026
·
attack.initial-access
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Touch Suspicious Service File
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Default LockFile
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Execve Hijack
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Triple Cross eBPF Rootkit Install Commands
calendar
Apr 28, 2026
·
attack.stealth
attack.t1014
·
Share on:
twitter
facebook
linkedin
copy
Troubleshooting Pack Cmdlet Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Trusted Path Bypass via Windows Directory Spoofing
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.007
attack.t1548.002
·
Share on:
twitter
facebook
linkedin
copy
Turla Group Commands May 2020
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.stealth
attack.g0010
attack.execution
attack.t1059.001
attack.t1053.005
attack.t1027
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using Event Viewer RecentViews
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass Using EventVwr
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UAC Bypass With Fake DLL
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1548.002
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
UEFI Persistence Via Wpbbin - FileCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.t1542.001
·
Share on:
twitter
facebook
linkedin
copy
UEFI Persistence Via Wpbbin - ProcessCreation
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
attack.t1542.001
·
Share on:
twitter
facebook
linkedin
copy
Unauthorized System Time Modification
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.006
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Barracuda ESG Exploitation Indicators
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Download Compressed Files From Temp.sh Using Wget
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Download Tar File From Untrusted Direct IP Via Wget
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - Email Exfiltration File Pattern
calendar
Apr 28, 2026
·
attack.execution
attack.persistence
detection.emerging-threats
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
UNC4841 - SSL Certificate Exfiltration Via Openssl
calendar
Apr 28, 2026
·
attack.stealth
attack.t1140
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon AddinUtil.EXE CommandLine Execution
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of AddinUtil.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Appvlp.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of BgInfo.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Conhost.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Defaultpack.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Of Setres.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Child Process Spawned By Odbcconf.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.008
·
Share on:
twitter
facebook
linkedin
copy
Uncommon File Creation By Mysql Daemon Process
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Uncommon FileSystem Load Attempt By Format.com
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Link.EXE Parent Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Process Access Rights For Target Image
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1055.011
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Sigverif.EXE Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Svchost Command Line Parameter
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.t1036.005
attack.t1055
attack.t1055.012
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Svchost Parent Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Unfamiliar Sign-In Properties
calendar
Apr 28, 2026
·
attack.stealth
attack.t1078
attack.persistence
attack.privilege-escalation
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Unmount Share Via Net.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1070.005
·
Share on:
twitter
facebook
linkedin
copy
Unsigned .node File Loaded
calendar
Apr 28, 2026
·
attack.execution
attack.privilege-escalation
attack.persistence
attack.stealth
attack.t1129
attack.t1574.001
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Unsigned AppX Installation Attempt Using Add-AppxPackage
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript
calendar
Apr 28, 2026
·
attack.persistence
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Binary Loaded From Suspicious Location
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned DLL Loaded by Windows Utility
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218.011
attack.t1218.010
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Mfdetours.DLL Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unsigned Module Loaded by ClickOnce Application
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Download from Direct IP Address
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Unusual File Download From File Sharing Websites - File Stream
calendar
Apr 28, 2026
·
attack.stealth
attack.s0139
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Use Icacls to Hide File to Everyone
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.001
·
Share on:
twitter
facebook
linkedin
copy
Use NTFS Short Name in Command Line
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Use NTFS Short Name in Image
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
Use Of Hidden Paths Or Files
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Use of Legacy Authentication Protocols
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.credential-access
attack.stealth
attack.t1078.004
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Use of Remote.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use of Scriptrunner.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Use Of The SFTP.EXE Binary As A LOLBIN
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Use of TTDInject.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use of VisualUiaVerifyNative.exe
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Use of VSIISExeLauncher.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use of Wfc.exe
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1127
·
Share on:
twitter
facebook
linkedin
copy
Use Short Name Path in Image
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.004
·
Share on:
twitter
facebook
linkedin
copy
User Access Blocked by Azure Conditional Access
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.credential-access
attack.initial-access
attack.stealth
attack.t1110
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Dscl
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via DseditGroup
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added To Admin Group Via Sysadminctl
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.003
·
Share on:
twitter
facebook
linkedin
copy
User Added to an Administrator's Azure AD Role
calendar
Apr 28, 2026
·
attack.initial-access
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1098.003
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
User Added to Local Administrator Group
calendar
Apr 28, 2026
·
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078
attack.persistence
attack.t1098
·
Share on:
twitter
facebook
linkedin
copy
User Added To Privilege Role
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
User State Changed From Guest To Member
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Added to Global or Device Admin Roles
calendar
Apr 28, 2026
·
attack.persistence
attack.initial-access
attack.privilege-escalation
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Users Authenticating To Other Azure AD Tenants
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.initial-access
attack.stealth
attack.t1078.004
·
Share on:
twitter
facebook
linkedin
copy
Using SettingSyncHost.exe as LOLBin
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.008
·
Share on:
twitter
facebook
linkedin
copy
UtilityFunctions.ps1 Proxy Dll
calendar
Apr 28, 2026
·
attack.stealth
attack.t1216
·
Share on:
twitter
facebook
linkedin
copy
Verclsid.exe Runs COM Object
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Virtualbox Driver Installation or Starting of VMs
calendar
Apr 28, 2026
·
attack.stealth
attack.t1564.006
attack.t1564
·
Share on:
twitter
facebook
linkedin
copy
Visual Basic Command Line Compiler Usage
calendar
Apr 28, 2026
·
attack.stealth
attack.t1027.004
·
Share on:
twitter
facebook
linkedin
copy
Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Visual Studio NodejsTools PressAnyKey Renamed Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
VMGuestLib DLL Sideload
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Signed Dbghelp.DLL Potential Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
VMMap Unsigned Dbghelp.DLL Potential Sideloading
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
Wab Execution From Non Default Location
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Wab/Wabmig Unusual Parent Or Child Processes
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Weak or Abused Passwords In CLI
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Win Susp Computer Name Containing Samtheadmin
calendar
Apr 28, 2026
·
attack.initial-access
cve.2021-42278
cve.2021-42287
attack.persistence
attack.privilege-escalation
attack.stealth
attack.t1078
·
Share on:
twitter
facebook
linkedin
copy
Windows Binaries Write Suspicious Extensions
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Windows Binary Executed From WSL
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
Windows Kernel Debugger Execution
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Windows MSIX Package Support Framework AI_STUBS Execution
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.defense-impairment
attack.t1218
attack.t1553.005
attack.t1204.002
·
Share on:
twitter
facebook
linkedin
copy
Windows Processes Suspicious Parent Directory
calendar
Apr 28, 2026
·
attack.stealth
attack.t1036.003
attack.t1036.005
·
Share on:
twitter
facebook
linkedin
copy
Windows Service Terminated With Error
calendar
Apr 28, 2026
·
attack.stealth
·
Share on:
twitter
facebook
linkedin
copy
Windows Shell/Scripting Processes Spawning Suspicious Programs
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.005
attack.t1059.001
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Windows Spooler Service Suspicious Binary Load
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.execution
attack.stealth
attack.t1574
cve.2021-1675
cve.2021-34527
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Winnti Malware HK University Campaign
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Winnti Pipemon Characteristics
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
attack.g0044
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Winrs Local Command Execution
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.stealth
attack.t1021.006
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
Wlrmdr.EXE Uncommon Argument Or Child Process
calendar
Apr 28, 2026
·
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
WMIC Loading Scripting Libraries
calendar
Apr 28, 2026
·
attack.stealth
attack.t1220
·
Share on:
twitter
facebook
linkedin
copy
Writing Of Malicious Files To The Fonts Folder
calendar
Apr 28, 2026
·
attack.stealth
attack.t1211
attack.t1059
attack.persistence
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
WSL Child Process Anomaly
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
WSL Kali-Linux Usage
calendar
Apr 28, 2026
·
attack.stealth
attack.t1202
·
Share on:
twitter
facebook
linkedin
copy
XBAP Execution From Uncommon Locations Via PresentationHost.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1218
·
Share on:
twitter
facebook
linkedin
copy
XSL Script Execution Via WMIC.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.t1047
attack.t1220
attack.execution
attack.t1059.005
attack.t1059.007
·
Share on:
twitter
facebook
linkedin
copy
Xwizard.EXE Execution From Non-Default Location
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.persistence
attack.execution
attack.stealth
attack.t1574.001
·
Share on:
twitter
facebook
linkedin
copy
ZxShell Malware
calendar
Apr 28, 2026
·
attack.execution
attack.stealth
attack.t1059.003
attack.t1218.011
attack.s0412
attack.g0001
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
to-top